The Experts below are selected from a list of 51 Experts worldwide ranked by ideXlab platform
Kim-kwang Raymond Choo - One of the best experts on this subject based on the ideXlab platform.
-
P4-to-blockchain: A secure blockchain-enabled packet parser for software defined networking
Computers & Security, 2020Co-Authors: Abbas Yazdinejad, Reza M. Parizi, Ali Dehghantanha, Kim-kwang Raymond ChooAbstract:Abstract Security is one of the most challenging issues in software defined networking (SDN), and causes include the inability to detect the contents of the packets. In addition, file transferring to SDN is a Potential Attack Vector that can be exploited at the network level. On the SDN data plane (i.e. the switch), packets are processed so that their behavior in the network can be determined. Packet parser (PP) acts as the main role of this operation on the switch. PP plays a very important role in identifying packets and supporting protocols and testing new ideas in SDN, which requires packet parsers on the data plane to provide the necessary flexibility and programmability. In recent times, cryptographic ledger technology (also referred to as Blockchain in the literature) has been applied to securely transfer transactions and files in the networks, mainly for crypto payments. In this paper, we propose a new packet parser architecture called Blockchain-enabled Packet Parser (BPP) based on the security characteristics of the blockchain and support for data processing functions with the description of Programming Protocol-Independent Packet Processors (P4) language that has the BPP-independent attribute of the protocol. In the proposed architecture, we provide a mathematical model based on a multivariate correlation approach for Attack detection from the observed packet traffic. The implementation of BPP architecture is on Field Programmable Gate Array (FPGA), which is known for its higher processing speed, flexibility, and lower consumption resources. The result indicates that the proposed BPP is able to detect Attacks and policy performed on the control plane in how to detect an Attack from a packet structure efficiently. Furthermore, the impact of the bandwidth with and without the BPP in hardware environment is evaluated to demonstrate BPP's efficiency.
-
Circumventing iOS security mechanisms for APT forensic investigations: A security taxonomy for cloud apps
Future Generation Computer Systems, 2018Co-Authors: Christian J. D'orazio, Kim-kwang Raymond ChooAbstract:Mobile devices and apps such as cloud apps are a Potential Attack Vector in an advanced persistent threat (APT) incident, due to their capability to store sensitive data (e.g. backup of private and personal data in digital repositories) and access sensitive resources (e.g. compromising the device to access an organisational network). These devices and apps are, thus, a rich source of digital evidence. It is vital to be able to identify artefacts of forensic interest transmitted to/from and stored on the devices. However, security mechanisms in mobile platforms and apps can complicate the forensic acquisition of data. In this paper, we present techniques to circumvent security mechanisms and facilitate collection of artefacts from cloud apps. We then demonstrate the utility of the circumvention techniques using 18 popular iOS cloud apps as case studies. Based on the findings, we present the first iOS cloud app security taxonomy that could be used in the investigation of an APT incident.
-
always connected but are smart mobile users getting more security savvy a survey of smart mobile device users
Behaviour & Information Technology, 2014Co-Authors: James Imgraben, Alewyn Engelbrecht, Kim-kwang Raymond ChooAbstract:Smart mobile devices are a Potential Attack Vector for cyber criminal activities. Two hundred and fifty smart mobile device owners from the University of South Australia were surveyed. Not surprisingly, it was found that smart mobile device users in the survey generally underestimated the value that their collective identities have to criminals and how these can be sold. For example, participants who reported jail-breaking/rooting their devices were also more likely to exhibit risky behaviour (e.g. downloading and installing applications from unknown providers), and the participants generally had no idea of the value of their collective identities to criminals which can be sold to the highest bidder. In general, the participants did not understand the risks and may not have perceived cyber crime to be a real threat. Findings from the survey and the escalating complexities of the end-user mobile and online environment underscore the need for regular ongoing training programs for basic online security and t...
-
information security in the south australian real estate industry a study of 40 real estate organisations
Information Management & Computer Security, 2014Co-Authors: Deepa Mani, Kim-kwang Raymond Choo, Sameera MubarakAbstract:Purpose - Opportunities for malicious cyber activities have expanded with the globalisation and advancements in information and communication technology (ICT). Such activities will increasingly affect the security of businesses with online presence and/or connected to the Internet. Although the real estate sector is a Potential Attack Vector for and target of malicious cyber activities, it is an understudied industry. This paper aims to contribute to a better understanding of the information security threats, awareness, and risk management standards currently employed by the real estate sector in South Australia.Design/methodology/approach - Current study comprises both quantitative and qualitative methodologies, which include 20 survey questionnaires and 20 face-to-face interviews conducted in South Australia. Findings - There is a lack of understanding about the true magnitude of malicious cyber activities and its impact on the real estate sector, as illustrated in our findings of 40 real estate organisations in South Australia. Our findings and the escalating complexities of the online environment underscore the need for regular ongoing training programs for basic online security (including new cybercrime trends) and the promotion of a culture of information security (e.g. when using smart mobile devices to store and access sensitive data) among staff. Such initiatives will enable staff employed in the (South Australian) real estate sector to maintain current knowledge of the latest. Originality/value - This is the first academic study focusing on the real estate organisations in South Australia. Our findings will contribute to the evidence on the information security threats faced by the sector as well as in develop sector-specific information security risk management guidelines.
-
Information security in the South Australian real estate industry: A study of 40 real estate organisations
Information Management and Computer Security, 2014Co-Authors: Deepa Mani, Kim-kwang Raymond Choo, Sameera MubarakAbstract:Purpose – Opportunities for malicious cyber activities have expanded with the globalisation and advancements in information and communication technology. Such activities will increasingly affect the security of businesses with online presence and/or connected to the internet. Although the real estate sector is a Potential Attack Vector for and target of malicious cyber activities, it is an understudied industry. This paper aims to contribute to a better understanding of the information security threats, awareness, and risk management standards currently employed by the real estate sector in South Australia. Design/methodology/approach – The current study comprises both quantitative and qualitative methodologies, which include 20 survey questionnaires and 20 face-to-face interviews conducted in South Australia. Findings – There is a lack of understanding about the true magnitude of malicious cyber activities and its impact on the real estate sector, as illustrated in the findings of 40 real estate organisations in South Australia. The findings and the escalating complexities of the online environment underscore the need for regular ongoing training programs for basic online security (including new cybercrime trends) and the promotion of a culture of information security (e.g. when using smart mobile devices to store and access sensitive data) among staff. Such initiatives will enable staff employed in the (South Australian) real estate sector to maintain the current knowledge of the latest cybercrime activities and the best cyber security protection measures available. Originality/value – This is the first academic study focusing on the real estate organisations in South Australia. The findings will contribute to the evidence on the information security threats faced by the sector as well as in develop sector-specific information security risk management guidelines.
Sameera Mubarak - One of the best experts on this subject based on the ideXlab platform.
-
information security in the south australian real estate industry a study of 40 real estate organisations
Information Management & Computer Security, 2014Co-Authors: Deepa Mani, Kim-kwang Raymond Choo, Sameera MubarakAbstract:Purpose - Opportunities for malicious cyber activities have expanded with the globalisation and advancements in information and communication technology (ICT). Such activities will increasingly affect the security of businesses with online presence and/or connected to the Internet. Although the real estate sector is a Potential Attack Vector for and target of malicious cyber activities, it is an understudied industry. This paper aims to contribute to a better understanding of the information security threats, awareness, and risk management standards currently employed by the real estate sector in South Australia.Design/methodology/approach - Current study comprises both quantitative and qualitative methodologies, which include 20 survey questionnaires and 20 face-to-face interviews conducted in South Australia. Findings - There is a lack of understanding about the true magnitude of malicious cyber activities and its impact on the real estate sector, as illustrated in our findings of 40 real estate organisations in South Australia. Our findings and the escalating complexities of the online environment underscore the need for regular ongoing training programs for basic online security (including new cybercrime trends) and the promotion of a culture of information security (e.g. when using smart mobile devices to store and access sensitive data) among staff. Such initiatives will enable staff employed in the (South Australian) real estate sector to maintain current knowledge of the latest. Originality/value - This is the first academic study focusing on the real estate organisations in South Australia. Our findings will contribute to the evidence on the information security threats faced by the sector as well as in develop sector-specific information security risk management guidelines.
-
Information security in the South Australian real estate industry: A study of 40 real estate organisations
Information Management and Computer Security, 2014Co-Authors: Deepa Mani, Kim-kwang Raymond Choo, Sameera MubarakAbstract:Purpose – Opportunities for malicious cyber activities have expanded with the globalisation and advancements in information and communication technology. Such activities will increasingly affect the security of businesses with online presence and/or connected to the internet. Although the real estate sector is a Potential Attack Vector for and target of malicious cyber activities, it is an understudied industry. This paper aims to contribute to a better understanding of the information security threats, awareness, and risk management standards currently employed by the real estate sector in South Australia. Design/methodology/approach – The current study comprises both quantitative and qualitative methodologies, which include 20 survey questionnaires and 20 face-to-face interviews conducted in South Australia. Findings – There is a lack of understanding about the true magnitude of malicious cyber activities and its impact on the real estate sector, as illustrated in the findings of 40 real estate organisations in South Australia. The findings and the escalating complexities of the online environment underscore the need for regular ongoing training programs for basic online security (including new cybercrime trends) and the promotion of a culture of information security (e.g. when using smart mobile devices to store and access sensitive data) among staff. Such initiatives will enable staff employed in the (South Australian) real estate sector to maintain the current knowledge of the latest cybercrime activities and the best cyber security protection measures available. Originality/value – This is the first academic study focusing on the real estate organisations in South Australia. The findings will contribute to the evidence on the information security threats faced by the sector as well as in develop sector-specific information security risk management guidelines.
Jeff Rowe - One of the best experts on this subject based on the ideXlab platform.
-
Is Anybody Home? Inferring Activity From Smart Home Network Traffic
2016 IEEE Security and Privacy Workshops (SPW), 2016Co-Authors: Bogdan Copos, Karl Levitt, Matt Bishop, Jeff RoweAbstract:As smart home devices are introduced into our homes, security and privacy concerns are being raised. Smart home devices collect, exchange, and transmit various data about the environment of our homes. This data can not only be used to characterize a physical property but also to infer personal information about the inhabitants. One Potential Attack Vector for smart home devices is the use of traffic classification as a source for covert channel Attacks. Specifically, we are concerned with the use of traffic classification techniques for inferring events taking place within a building. In this work, we study two of the most popular smart home devices, the Nest Thermostat and the wired Nest Protect (i.e. smoke and carbon dioxide detector) and show that traffic analysis can be used to learn Potentially sensitive information about the state of a smart home. Among other observations, we show that we can determine, with 88% and 67% accuracy respectively, when the thermostat transitions between the Home and Auto Away mode and vice versa, based only on network traffic originating from the device. This information may be used, for example, by an Attacker to infer whether the home is occupied.
-
IEEE Symposium on Security and Privacy Workshops - Is Anybody Home? Inferring Activity From Smart Home Network Traffic
2016 IEEE Security and Privacy Workshops (SPW), 2016Co-Authors: Bogdan Copos, Matt Bishop, Karl N. Levitt, Jeff RoweAbstract:As smart home devices are introduced into our homes, security and privacy concerns are being raised. Smart home devices collect, exchange, and transmit various data about the environment of our homes. This data can not only be used to characterize a physical property but also to infer personal information about the inhabitants. One Potential Attack Vector for smart home devices is the use of traffic classification as a source for covert channel Attacks. Specifically, we are concerned with the use of traffic classification techniques for inferring events taking place within a building. In this work, we study two of the most popular smart home devices, the Nest Thermostat and the wired Nest Protect (i.e. smoke and carbon dioxide detector) and show that traffic analysis can be used to learn Potentially sensitive information about the state of a smart home. Among other observations, we show that we can determine, with 88% and 67% accuracy respectively, when the thermostat transitions between the Home and Auto Away mode and vice versa, based only on network traffic originating from the device. This information may be used, for example, by an Attacker to infer whether the home is occupied.
-
Is Anybody Home? Inferring Activity From Smart Home Network Traffic - eScholarship
2016Co-Authors: Bogdan Copos, Matt Bishop, Karl N. Levitt, Jeff RoweAbstract:Is Anybody Home? Inferring Activity From Smart Home Network Traffic Bogdan Copos ∗ , Karl Levitt † , Matt Bishop ‡ , Jeff Rowe § Department of Computer Science University of California, Davis Email: ∗ bcopos@ucdavis.edu, † levitt@cs.ucdavis.edu, ‡ mabishop@ucdavis.edu, § rowe@cs.cdavis.edu, Abstract—As smart home devices are introduced into our homes, security and privacy concerns are being raised. Smart home devices collect, exchange, and transmit various data about the environment of our homes. This data can not only be used to characterize a physical property but also to infer personal information about the inhabitants. One Potential Attack Vector for smart home devices is the use of traffic classification as a source for covert channel Attacks. Specifically, we are concerned with the use of traffic classification techniques for inferring events taking place within a building. In this work, we study two of the most popular smart home devices, the Nest Thermostat and the wired Nest Protect (i.e. smoke and carbon dioxide detector) and show that traffic analysis can be used to learn Potentially sensitive information about the state of a smart home. Among other observations, we show that we can determine, with 88% and 67% accuracy respectively, when the thermostat transitions between the Home and Auto Away mode and vice versa, based only on network traffic originating from the device. This information may be used, for example, by an Attacker to infer whether the home is occupied. I. I NTRODUCTION Smart home devices are becoming increasingly popular in households around the world. Nest Labs, one of the most popular manufacturers of smart thermostats and smoke detectors, is believed to have sold 440,000 smoke detector units over the span of four months in 2014 alone. Smart home devices are designed to help homeowners automate and simplify mundane tasks around their property. However, bringing internet connectivity to household devices has also introduced many security and privacy concerns. At the end of 2015, security researchers discovered a vulnerability in Barbie dolls which would allow Attackers to not only steal personal information but also convert a doll into a spying device capable of listening into conversations [6]. In early 2016, security research from Rapid7 found vulnerabilities in Comcast’s Xfinity Home Security system that would cause the system to not report when a property’s windows and/or doors were compromised [19]. In this paper, we investigate how device-to-device and device-to-cloud smart home network traffic can be used to infer personal information. Specifically, we use traffic analysis techniques on network traffic generated by devices from Nest Labs to learn information about the presence of residents and other events occurring within the property. Traffic analysis is the process of intercepting and analyzing network packets in order to deduce information from patterns in communication. The experiments involve two smart home devices, a smart thermostat and a smart smoke and carbon dioxide detector. The rest of the paper is organized as follows: • Section II describes relevant previous work. • Section III gives a detailed rundown of the devices used in this study and their features and capabilities. • In Section IV the data collection process is described. • In Section V, the methodology behind the traffic classi- fication is explained. • Section VI reports the findings of our analysis. • Section VII describes how the findings were tested for validity and presents information about the accuracy of our findings. • Section VIII discusses limitations of our approach. • In section IX we provide some initial ideas for solutions and list possible future work. II. P REVIOUS W ORK Traffic analysis Attacks were highlighted in “Attacks of the SSL 3.0 protocol” [16], by Wagner and Schneier who showed the URL of an HTTP GET request is leaked in SSL because cipher-texts fail to disguise the plaintext length. Later, Cheng and Avnur [3] show that websites can be fingerprinted by performing traffic analysis of SSL encrypted web browsing traffic. Ever since, there have been a number of works [2], [7], [8], [10], [13], [15] exploring traffic analysis Attacks using various features including source and destination attributes (e.g. address, port), protocol, packet and connection sizes, and even timing information (e.g. duration of connec- tions, burstiness of transmissions). Efforts have also been put into developing countermeasures for such Attacks [5], [11], [18]. Countermeasure techniques include traffic padding and traffic masking. Another variation is in the implementation, whether server side, client side, or both. Recently, in “Peek-a-Boo, I Still See You: Why Efficient Traffic Analysis Countermeasures Fail” [4], Dyer, Coull et. al. provide the first comprehensive analysis of some of the proposed traffic analysis countermeasures and show why they fail to protect against Attacks. The authors argue that there is no efficient solution.
James Imgraben - One of the best experts on this subject based on the ideXlab platform.
-
always connected but are smart mobile users getting more security savvy a survey of smart mobile device users
Behaviour & Information Technology, 2014Co-Authors: James Imgraben, Alewyn Engelbrecht, Kim-kwang Raymond ChooAbstract:Smart mobile devices are a Potential Attack Vector for cyber criminal activities. Two hundred and fifty smart mobile device owners from the University of South Australia were surveyed. Not surprisingly, it was found that smart mobile device users in the survey generally underestimated the value that their collective identities have to criminals and how these can be sold. For example, participants who reported jail-breaking/rooting their devices were also more likely to exhibit risky behaviour (e.g. downloading and installing applications from unknown providers), and the participants generally had no idea of the value of their collective identities to criminals which can be sold to the highest bidder. In general, the participants did not understand the risks and may not have perceived cyber crime to be a real threat. Findings from the survey and the escalating complexities of the end-user mobile and online environment underscore the need for regular ongoing training programs for basic online security and t...
Deepa Mani - One of the best experts on this subject based on the ideXlab platform.
-
information security in the south australian real estate industry a study of 40 real estate organisations
Information Management & Computer Security, 2014Co-Authors: Deepa Mani, Kim-kwang Raymond Choo, Sameera MubarakAbstract:Purpose - Opportunities for malicious cyber activities have expanded with the globalisation and advancements in information and communication technology (ICT). Such activities will increasingly affect the security of businesses with online presence and/or connected to the Internet. Although the real estate sector is a Potential Attack Vector for and target of malicious cyber activities, it is an understudied industry. This paper aims to contribute to a better understanding of the information security threats, awareness, and risk management standards currently employed by the real estate sector in South Australia.Design/methodology/approach - Current study comprises both quantitative and qualitative methodologies, which include 20 survey questionnaires and 20 face-to-face interviews conducted in South Australia. Findings - There is a lack of understanding about the true magnitude of malicious cyber activities and its impact on the real estate sector, as illustrated in our findings of 40 real estate organisations in South Australia. Our findings and the escalating complexities of the online environment underscore the need for regular ongoing training programs for basic online security (including new cybercrime trends) and the promotion of a culture of information security (e.g. when using smart mobile devices to store and access sensitive data) among staff. Such initiatives will enable staff employed in the (South Australian) real estate sector to maintain current knowledge of the latest. Originality/value - This is the first academic study focusing on the real estate organisations in South Australia. Our findings will contribute to the evidence on the information security threats faced by the sector as well as in develop sector-specific information security risk management guidelines.
-
Information security in the South Australian real estate industry: A study of 40 real estate organisations
Information Management and Computer Security, 2014Co-Authors: Deepa Mani, Kim-kwang Raymond Choo, Sameera MubarakAbstract:Purpose – Opportunities for malicious cyber activities have expanded with the globalisation and advancements in information and communication technology. Such activities will increasingly affect the security of businesses with online presence and/or connected to the internet. Although the real estate sector is a Potential Attack Vector for and target of malicious cyber activities, it is an understudied industry. This paper aims to contribute to a better understanding of the information security threats, awareness, and risk management standards currently employed by the real estate sector in South Australia. Design/methodology/approach – The current study comprises both quantitative and qualitative methodologies, which include 20 survey questionnaires and 20 face-to-face interviews conducted in South Australia. Findings – There is a lack of understanding about the true magnitude of malicious cyber activities and its impact on the real estate sector, as illustrated in the findings of 40 real estate organisations in South Australia. The findings and the escalating complexities of the online environment underscore the need for regular ongoing training programs for basic online security (including new cybercrime trends) and the promotion of a culture of information security (e.g. when using smart mobile devices to store and access sensitive data) among staff. Such initiatives will enable staff employed in the (South Australian) real estate sector to maintain the current knowledge of the latest cybercrime activities and the best cyber security protection measures available. Originality/value – This is the first academic study focusing on the real estate organisations in South Australia. The findings will contribute to the evidence on the information security threats faced by the sector as well as in develop sector-specific information security risk management guidelines.